Busable Hub Privacy Policy

What the Busable Hub™ driver app collects, why, and who can see it

About this policy

Busable Hub is the driver app for bus and coach operators who run their business on Busable. You use it because the operator you drive for has given you access. This policy explains what the app collects from your phone, what it does with it, and what your operator can see.

The app is made by Cortexus Pty Ltd trading as Busable (ACN 654 917 021) ("Busable", "we", "us"). We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy sits alongside our general Privacy Policy, which covers our website and platform. Where the two differ, this policy applies to the Busable Hub app.

Your operator is your employer or contracting principal. Records the app creates about your work, such as which shifts you drove and how the service ran to time, belong to your operator and are held by Busable on their behalf. Your operator decides how those records are used within their business, subject to workplace law and their own policies.

Permissions the app asks for

Busable Hub asks for three phone permissions. Each one is used for a specific job and nothing else. You can grant or withdraw any of them at any time in your phone's Settings.

Location

The app uses your location only while you have a shift running. It uses it to follow your route on the map, show your next stop, warn you if you are off route, and record the time you arrived at each stop so the operator has an on-time running record for the service.

If you allow background location, tracking keeps going when your screen is off or you switch to another app during a shift. Your phone shows the usual indicator whenever the app is using your location in the background. If you only allow location while using the app, tracking pauses when the app is not on screen and the stop arrival record for that part of the run will have gaps.

While a shift is running, the app sends the vehicle's position to Busable every few seconds. Your operator sees it as the live position of that vehicle on the service you are driving. Your operator may also pass the vehicle's live position on to passengers through its passenger information services, so people waiting at a stop can see where the bus is. Passengers see the vehicle and the service, not your name.

When you end the shift, the app also sends the stop arrival record: for each stop, the scheduled time, your actual arrival time and the difference, plus a summary of how the shift ran to time. Break start and end times are sent as they happen. Position fixes recorded while the app is in the background or out of coverage are held on the phone and sent when the app is next able to.

Location is not collected when no shift is running. It is not used to track you outside work.

Camera and photos

The app asks for camera or photo library access only when you choose to attach a photo to a vehicle defect report. The photo you take or pick is uploaded to Busable and attached to that defect record, where your operator's maintenance staff can see it. The app does not open the camera on its own, does not scan your photo library, and does not upload anything you have not chosen to attach.

The app does not record audio or video. Your phone may list a microphone permission for Busable Hub because of the photo component the app uses, but the app never asks for it and never turns the microphone on.

Notifications

Notifications tell you when your roster is published or a shift needs your response. To deliver them, the app registers a push token for your device with Busable, along with the app's bundle identifier and a device session identifier. The token lets Apple's notification service reach your phone; it does not identify you by name and cannot be used to read anything on your phone.

You can turn notifications off in the app's Preferences or in your phone's Settings. When you sign out, the app removes the token from Busable.

Information you provide

When you create an account you give us your email address, first name, last name and a password. Your password is stored in hashed form by our identity provider and is never visible to Busable staff or your operator. If your operator requires it, you may also set up two-factor authentication.

Your account is linked to the employee record your operator already holds for you in Busable. That record is created and maintained by your operator, not by the app.

While using the app you may also provide:

  • vehicle defect reports, including the fault description and any photos you attach;
  • incident reports, including the incident type, where it happened, the vehicle and route involved, what happened and what you did about it;
  • your response to a rostered shift, and the vehicle you select when you start one;
  • leave requests, including the dates and the type of leave;
  • break start and end times during a shift;
  • feedback you enter when ending a shift;
  • the vehicle and colour you pick for your profile avatar.

Defect and incident reports are sent to your operator. They may include information about other people, such as a passenger involved in an incident. Only include what your operator needs to deal with the report.

Information the app creates

As you work, the app creates records of your shifts: when you started and ended, which vehicle you drove, the vehicle's position during the shift, stop arrival times, the on-time running summary, and breaks. Busable uses these to show you your run history and profile statistics, to show your operator where its vehicles are, and to give your operator on-time running and shift records for the services you drove.

The app does not include advertising or third-party analytics trackers.

What is stored on your phone

So the app keeps working in depots and on routes with poor coverage, it keeps a copy of your roster, routes, stops, shift details, run history and profile statistics on the phone. It also stores your preferences, your push token, and any shift end or location data that is waiting to be sent when coverage returns.

This data stays on the phone and is removed when you delete the app. Account details are cleared when you sign out.

Who can see your information

  • Your operator. The vehicle's live position while you are on shift, shift records, on-time running, defect and incident reports, and your responses to rostered shifts are visible to the operator you drive for, through the Busable platform.
  • Passengers. If your operator publishes live vehicle positions, passengers can see where the vehicle is on the service you are driving. They are not shown your name or any other detail about you.
  • Busable. Our staff may access your information to run and support the service, investigate a problem, or where the law requires it.
  • Service providers. We host Busable on Amazon Web Services in Sydney, Australia. This includes account sign-in, the app's servers and photo storage. Map tiles are provided by Mapbox, which receives the map requests needed to draw the map on your screen and may collect anonymised usage information about the map under its own privacy policy. Push notifications are delivered through Apple's notification service. Each of these providers handles data under its own privacy policy.
  • Authorities. We may disclose information to law enforcement, regulators or other government bodies where required or authorised by law.

We do not sell your personal information and do not share it with advertisers.

Security

All traffic between the app and Busable is encrypted in transit. Sign-in is handled by Amazon Cognito, and every request the app makes to Busable is authenticated with your session. Photos are uploaded to private storage using short-lived, single-use upload links. We maintain physical, electronic and procedural safeguards over the systems that hold your information.

How long we keep it

Shift, vehicle position, on-time running, defect and incident records are operational records of your operator's business. They are kept for as long as your operator's contracts, safety obligations and record-keeping requirements need them, and are managed under the operator's agreement with Busable.

Your account details are kept while your account is active. Push tokens are removed when you sign out or turn notifications off.

Your choices

  • Permissions. Change location, camera, photo and notification access at any time in your phone's Settings. Location is needed to run a shift with route guidance and on-time running; the other permissions are optional.
  • Notifications. Turn them off in the app's Preferences.
  • Delete your account. Use Delete account in the app's Settings. This removes your sign-in and your driver profile from Busable. Shift and report records already delivered to your operator remain part of the operator's records.
  • Access and correction. To see or correct the personal information Busable holds about you, contact us using the details below. For records held by your operator, contact your operator first.

Changes to this policy

We may update this policy when the app changes. The current version is always at www.busable.app/privacy-busable-hub. If a change means the app collects something new, we will ask for the relevant permission before it takes effect.

Complaints

If you think we have handled your personal information in breach of this policy or the Australian Privacy Principles, email [email protected] or write to Level 13 / 477 Pitt St, Sydney 2000. Include your contact details so we can respond. We will reply within 28 days of receiving the complaint.

If you are not satisfied with our response, you can take your complaint to the Office of the Australian Information Commissioner (www.oaic.gov.au or 1300 363 992).

Contact us

Questions about this policy or the Busable Hub app:

Email: [email protected]
Privacy: [email protected]
Address: Level 13 / 477 Pitt St, Sydney 2000

Last updated: 1 September 2026
Effective date: 1 September 2026
Applies to: Busable Hub for iOS and Android
Company: Cortexus Pty Ltd trading as Busable (ACN 654 917 021)